Adobe Flash - Out-of-Bounds Read in applyToRange

Google Security Research 2017-09-25 dos multiple
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1323

The attached fuzzed file causes an out-of-bounds read in TextFormat.applyToRange.


Proof of Concept:
 
https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/42783.zip